Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 66003 - net-misc/proxytunnel: username/password handled insecurely
Summary: net-misc/proxytunnel: username/password handled insecurely
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/12685/
Whiteboard: C4 [ebuild] lewk
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-01 03:01 UTC by Matthias Geerdsen (RETIRED)
Modified: 2011-10-30 22:38 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Geerdsen (RETIRED) gentoo-dev 2004-10-01 03:01:44 UTC
http://secunia.com/advisories/12685/

Secunia Advisory:	SA12685
Software:	proxytunnel 1.x

Description:
A security issue has been reported in proxytunnel, which can be exploited by malicious, local users to gain knowledge of sensitive information.

The problem is that the username and password for the proxy is passed insecurely.

Solution:
The issue has been fixed in version 1.2.0.
http://sourceforge.net/project/showfiles.php?group_id=39840
___________________________________________________

from the CHANGES file
(http://cvs.sourceforge.net/viewcvs.py/proxytunnel/proxytunnel/CHANGES?rev=1.16&view=auto)
- Added patch by Fred Donck <fd0 at donck dot com> to store proxy username
  and password in environment variables.

  Security fix
  ------------

  - Modified cmdline.c to allow passing of proxyuser and proxypass as
    environment variables to prevent other users on same machine from
    snooping sensitive info.
    -U for env var that contains the proxy user
    -S for env var that contains the proxy user's password

______________________________________________________________________

package only has ~x86

vapier, since you commited this ebuild, could you please bump it
Comment 1 SpanKY gentoo-dev 2004-10-01 05:38:27 UTC
version bumped in cvs

previous version was ~x86, new version is x86
Comment 2 Matthias Geerdsen (RETIRED) gentoo-dev 2004-10-01 12:57:32 UTC
Closing without GLSA, since this was ~arch masked before and rated C4.